Galaxy Research has confirmed that the Coldcard bitcoin hack has resulted in losses of over $115 million. The hack, which started on July 31, exploited a firmware bug in Coldcard Mk3 devices, allowing hackers to guess investor seedphrases. According to Galaxy Research, the bug caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator.
The company has spoken with over 200 victims to support them and gather intelligence on the attackers. The figures are based on the price of bitcoin at the time of the attack. Galaxy Research estimates that at least 15 separate attackers were exploiting the bug independently.
Hack Details
Previous research from Galaxy found that the typical stolen coin had sat untouched for 3.5 years, and a striking 88% of pilfered funds were at least a year old. The firm is still confirming how much is stolen, and has said that total losses could exceed $130 million.
Coinkite, the Canadian company behind Coldcard, has urged investors to update their software or move their funds off the popular hardware wallet. The company said in a statement that the bug in its software 'silently went unnoticed' and 'its potential impact grew with every release' of its products.